CVE-2008-6449

Cross-site request forgery (CSRF) vulnerability in multiple Century Systems routers including XR-410 before 1.6.9, XR-510 before 3.5.3, XR-440 before 1.7.8, and other XR series routers from XR-510 to XR-730 allows remote attackers to modify configuration as the administrator via unknown vectors.
Configurations

Configuration 1 (hide)

OR cpe:2.3:h:centurysys:xr-1100:*:*:*:*:*:*:*:*
cpe:2.3:h:centurysys:xr-410:*:*:*:*:*:*:*:*
cpe:2.3:h:centurysys:xr-410-l2:*:*:*:*:*:*:*:*
cpe:2.3:h:centurysys:xr-440:*:*:*:*:*:*:*:*
cpe:2.3:h:centurysys:xr-510:*:*:*:*:*:*:*:*
cpe:2.3:h:centurysys:xr-540:*:*:*:*:*:*:*:*
cpe:2.3:h:centurysys:xr-640:*:*:*:*:*:*:*:*
cpe:2.3:h:centurysys:xr-640-l2:*:*:*:*:*:*:*:*
cpe:2.3:h:centurysys:xr-730:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2009-03-09 14:30

Updated : 2024-02-28 11:21


NVD link : CVE-2008-6449

Mitre link : CVE-2008-6449

CVE.ORG link : CVE-2008-6449


JSON object : View

Products Affected

centurysys

  • xr-410
  • xr-410-l2
  • xr-440
  • xr-640
  • xr-540
  • xr-730
  • xr-1100
  • xr-640-l2
  • xr-510
CWE
CWE-352

Cross-Site Request Forgery (CSRF)